Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38003

16
FAUCET Score

CVE-2025-38003 is a use-after-free vulnerability in the Linux kernel's CAN BCM subsystem, specifically affecting Debian and Linux kernel versions. It arises from missing RCU read protection when generating procfs content for bcm_op entries during removal, potentially leading to unreliable data output. Rated Medium (CVSS 5.5), this local vulnerability (AV:L/AC:L) could result in a high availability impact (A:H) without requiring user interaction. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite its low EPSS score.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19.252, < 4.20CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4.205, < 5.4.294CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10.130, < 5.10.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.15.54, < 5.15.185CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.18.11, < 5.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 49th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.92.2-2 on Azure Linux 3.0Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: 17085-17084Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: 19880-17084Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.1-1 on Azure Linux 3.0Fixed in: 6.6.96.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt

Vendor Advisories (10)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
microsoft2025-Jun/CVE-2025-38003Moderate

can: bcm: add missing rcu read protection for procfs content

Jun 10, 2025
redhatCVE-2025-38003Moderate

kernel: can: bcm: add missing rcu read protection for procfs content

Jun 8, 2025

References

git.kernel.org / stable/c/0622846db728a5332b917c797c733e202c4620ae
Patch
git.kernel.org / stable/c/19f553a1ddf260da6570ed8f8d91a8c87f49b63a
Patch
git.kernel.org / stable/c/1f912f8484e9c4396378c39460bbea0af681f319
Patch
git.kernel.org / stable/c/63567ecd99a24495208dc860d50fb17440043006
Patch
git.kernel.org / stable/c/659701c0b954ccdb4a916a4ad59bbc16e726d42c
Patch
git.kernel.org / stable/c/6d7d458c41b98a5c1670cbd36f2923c37de51cf5
Patch
git.kernel.org / stable/c/7c9db92d5f0eadca30884af75c53d601edc512ee
Patch
git.kernel.org / stable/c/dac5e6249159ac255dad9781793dbe5908ac9ddb
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Third Party Advisory